CRITICAL 9.2 NVD

CVE-2026-13737

CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance release. Up

CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.

References

Published: 2026-08-11 · Source: NVD · Feed updated: 2026-08-11
This critical severity vulnerability with a CVSS score of 9.2 was published on 2026-08-11 via NVD.

Risk Timeline

CVE Disclosed2026-08-11 · -1 days ago

Remediation Resources

vulnfeed aggregates 9850 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.